← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Jade Sleet Breaches Indian IT Provider Using FLATROOF and ROOFDECK macOS Backdoors

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Jade Sleet breached an Indian IT services provider.
  • The attack used FLATROOF and ROOFDECK macOS backdoors.
  • Social engineering with job interview lures was a key tactic.
  • Malware deployed via weaponized Terraform dependency files.

North Korean Threat Actor Targets IT Services

The North Korean threat actor group, Jade Sleet (also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899), has been linked to the compromise of a smaller IT services organization in India. This attack demonstrates the group's continued focus on targeting developers to gain access to target networks.

Deployment of macOS Backdoors

Cybersecurity firm SentinelOne reported that the attack involved the use of Apple macOS backdoors, FLATROOF (also called Gaslight) and ROOFDECK. These Rust-based malware families target ARM-based macOS systems. FLATROOF uses Telegram for command-and-control (C2) and can execute commands, upload/download files, and steal data via a Python module that collects browser information.

Social Engineering and Supply Chain Compromise

Jade Sleet employed social engineering tactics, specifically job interview lures, to target job seekers from companies they intended to breach. These lures often involve GitHub repositories designed as infrastructure engineering projects related to the target company. The attack chain leverages weaponized Terraform dependency lock files, which cause the download of attacker-controlled modules when a developer runs the 'terraform init' command.

History of Web3 and Cryptocurrency Targeting

Jade Sleet has a documented history of targeting the Web3 sector for cryptocurrency heists. Previous incidents include the theft of approximately $1.5 billion from Bybit's cold wallet infrastructure in early 2025, following a supply chain compromise of Safe{Wallet}'s developer environment. The group primarily targets users and vendors associated with cryptocurrency and blockchain organizations.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The North Korean threat actor Jade Sleet compromised an Indian IT services organization, deploying macOS backdoors FLATROOF and ROOFDECK. This incident highlights Jade Sleet's ongoing strategy of targeting developers and supply chains to breach networks, particularly within the Web3 sector.